JP Sheet is operated by List Networks Ltd, registered in the United Kingdom, and serves buyers worldwide. Our servers are in Manchester and our team works remotely — we keep no customer data in any office. To deliver our service, your personal data is processed in several countries β under specific legal safeguards. Here's exactly where, why, and how it's protected.
Last updated: 19 September 2026Your personal data may be transferred to and processed in any of the following five regions, each for a specific purpose:
JP Sheet is operated by List Networks Ltd, a company registered in the United Kingdom. Our application servers are in Manchester. Your account, your orders and your reports are stored here, under UK data protection law. We work remotely and hold no customer data in any office.
Our partner networks that retrieve original auction records sit on Japanese infrastructure. When you submit a chassis number, the lookup query is sent to Japan-based databases. Only the chassis number itself is transmitted β no buyer identity, no payment information.
When you order a US or Canada VIN check, the vehicle identification number only is sent to the record providers — NMVTIS (the federal vehicle title database), salvage auction houses and dealer listing networks. No personal data goes with it. They receive a VIN and return records about that vehicle; they are never told who asked.
Hosted analytics (Google Analytics β IP-anonymised) and marketing platforms (Meta/Facebook Pixel, Google Ads, TikTok Pixel β only with your cookie consent). Page-view and event data may be transferred to US-based servers operated by these providers.
Some payment processing is routed through Stripe and PayPal infrastructure that may include EU-based servers (depending on your billing country). Card data is handled entirely by these providers β JP Sheet never sees or stores it.
Static assets (CSS, images, fonts, public pages) are served via Cloudflare's global CDN, which has edge servers in 300+ cities. Cached content is non-personal. No authenticated or payment pages are cached on the edge.
A complete vendor-by-vendor breakdown for transparency:
| Vendor | What they process | Region |
|---|---|---|
| Stripe | Card numbers, expiry, CVV, billing email, amounts | US / EU (depends on your country) |
| PayPal | PayPal account email, transaction amounts | US / EU / Luxembourg |
| Google Analytics | Anonymised IP, page views, events (consent only) | US |
| Meta / Facebook Pixel | Conversion events, hashed identifiers (consent only) | US / Ireland |
| Google Ads | Conversion events, ad click identifiers (consent only); hashed email/phone for audience matching (Customer Match) | US |
| TikTok Pixel | Conversion events (consent only) | US / EU / Singapore |
| Cloudflare | IP addresses, request metadata (for security & CDN) | Global edge network |
| Gemini (Google AI) | Chassis number text only (for chassis decoder lookups) | US |
| Japanese auction partners | Chassis number only | Japan |
| Hostinger (hosting) | Application data, database | United Kingdom |
For data transfers out of the EU, UK and other regulated regions, we rely on the following safeguards:
SCCs are EU-approved contracts that legally bind any vendor to GDPR-level data protection β no matter where they process data. Stripe, PayPal, Google, Meta, TikTok and Cloudflare all maintain SCCs with their EU customers, which means our use of them inherits these protections.
Some non-EU countries have received "adequacy decisions" from the European Commission, meaning the EU has formally confirmed that their data protection laws meet GDPR-equivalent standards. Where your data is transferred to one of these countries, no further safeguard is required.
Countries with current adequacy decisions: UK, Switzerland, Japan, South Korea, Canada (commercial), New Zealand, Israel, Argentina, Uruguay, Andorra, Faroe Islands, Guernsey, Isle of Man, Jersey, US (under the EU-US Data Privacy Framework).
All data transfers between regions happen over TLS 1.3 (the latest standard). At rest, sensitive data is encrypted using industry-standard algorithms (AES-256 or better). This protects your data even if a vendor's transmission line is intercepted.
We only use vendors that publish their privacy and security commitments publicly, undergo independent audits (SOC 2, ISO 27001, PCI DSS where applicable), and provide GDPR-compliant data processing agreements.
Yes. Under GDPR Article 46, you have the right to request a copy of the appropriate safeguards (such as the SCCs) used to transfer your data outside the EU/UK.
To request a copy, email [email protected] with the subject line "Data Transfer Safeguards Request". We will provide the relevant documentation (or a link to the publicly available version) within 30 days.
If you live in the EU, UK, or another GDPR-equivalent jurisdiction, you have specific rights when your data is transferred internationally:
For a full list of your data rights, see our Data Rights page.
Email us β we'll answer specifically about your data, the vendors involved, and the safeguards.
Email [email protected]Related: Privacy Policy Β· Your Data Rights Β· California Privacy Β· Children's Privacy